
TeamPass v3.2.1.7
Collaborative Passwords Manager
Teampass
Self-hosted password management your whole team can trust
Folder-level access control · authenticated AES-256-GCM encryption · compliance evidence
Your secrets never leave your infrastructure.
🌐 teampass.net · 📖 Documentation · 💬 Discussions · 🐳 Docker Hub
Contents
- About
- Who it's for
- Security
- Features
- Get started
- Documentation
- Languages
- Community
- Support Teampass
- License
About
Teampass is an open-source credential vault you run yourself. No account to create, no company behind the curtain holding your data — just a PHP/MySQL application on your own server, with folder-level access control, per-user encryption keys and a full audit trail.
It has been built and maintained since 2009, driven by what real teams actually run into: who should see which credential, how to prove it to an auditor, and how to stop passwords living in chat threads and spreadsheets.
📸 More screenshots
Items and secrets
Folders and roles
Authentication and MFA
Encryption keys
Search, export, one-time view
Background tasks
Who it's for
🏠 Individuals & HomelabOwn your vault, literally.
|
👥 Teams & SMBStop sharing passwords in chat.
|
🏛️ Enterprise & RegulatedProve your access controls, don't just claim them.
|
Security
Encryption you can describe to an auditor
Secrets are encrypted with AES-256-GCM using random nonces and per-secret salts, under 256-bit object keys. The private key that unlocks them is derived from your password with PBKDF2-SHA256 at 600 000 iterations.
- Authenticated encryption — tampering is detected, not silently decrypted - Per-user key distribution — every user holds their own RSA-wrapped copy of each object key, so removing an account actually revokes access instead of just hiding a button
- Lazy migration — format upgrades happen on access, with no maintenance window
Transparency over silence
A password manager that reports no vulnerabilities is not a password manager that has none.
Findings are triaged, fixed and published as GitHub Security Advisories with CVE identifiers.